In IAM > Directory, you connect your organization’s identity provider, such as Okta, Microsoft Entra ID or Google Workspace, over OIDC or SAML 2.0, and verify the email domains its people use. People with an email address in a verified domain can sign in with SSO, and SCIM provisioning can create and manage them.
Identity providers are managed in the console.
Verified domains
A verified domain is an email domain your organization proved it owns by publishing a DNS TXT record. You list one or more email domains when you add an identity provider, and they’re verified together.
A verified domain:
- Lets people with an email address in it sign in through the identity provider. Nobody can sign in through a provider until its domains are verified.
- Lets SCIM provision people with an email address in it. SCIM refuses everyone else.
- While SCIM is on, can’t be invited: invitations to email addresses in it return
409withmanaged_by_scim.
An email address in a subdomain of a verified domain counts too: verifying example.com covers ada@eu.example.com.
The Directory page shows each provider’s status: Verified or Domain not verified. The API’s GetScimConfiguration returns your organization’s verified domains in verifiedDomains.
Permissions
| Action | Allows | Managed policies |
|---|---|---|
ssoProviders.list |
See identity providers, their domains and verification status | ReadOnlyAccess, IAMFullAccess |
ssoProviders.create |
Add identity providers | IAMFullAccess |
ssoProviders.verifyDomain |
Verify a provider’s domains | IAMFullAccess |
ssoProviders.update |
Change a provider’s group mapping | IAMFullAccess |
ssoProviders.delete |
Delete identity providers | IAMFullAccess |
ssoProviders.update, ssoProviders.verifyDomain and ssoProviders.delete can be scoped to one provider by its resource name, ezgh::org_…:sso_….
Add an identity provider
- Open IAM > Directory and select Add identity provider.
- Choose the Protocol, OIDC or SAML 2.0, and enter the Email domains, separated by commas:
example.com, example.org. - Enter your identity provider’s details:
- OIDC: the Issuer URL, Client ID and Client secret. Authorization endpoint is optional; set it only if browsers reach your provider at a different address than the issuer.
- SAML 2.0: the SSO URL and the IdP metadata XML.
- Optionally, map groups at your identity provider to groups in your organization. See Group mapping.
- Review, then select Add provider.
The console then shows what to configure at your identity provider: the Redirect URI for OIDC, or the Entity ID (audience), ACS URL and SP metadata for SAML. They’re also on the provider’s Setup tab.
Verify a domain
-
Open the provider under IAM > Directory and select the Domain verification tab.
-
At your DNS host, publish a TXT record for each domain the console lists, with its Name and the Value:
Type Name Value TXT_better-auth-token-sso_k3f9a0x2m7qp.example.comThe value the console shows The name is
_better-auth-token-, the provider ID, a dot and the domain. Every domain of the provider uses the same value. -
Once the records are published, select Verify domain.
Every listed domain must have a matching TXT record. If one doesn’t, verification fails with No matching TXT record found for <domain> yet and no domain is verified. DNS changes can take time to be visible; select Verify domain again later. If the console says the verification token expired, delete the provider and add it again.
Sign in with SSO
People sign in at https://login.ezghcloud.com/sign-in/sso with their work email address, or select Sign in with SSO on the sign-in page. Someone who isn’t in your organization yet joins it the first time they sign in. Signing in is refused when:
- Their account already belongs to another organization.
- An administrator removed them from your organization. They can sign in with SSO again once they’re invited back.
- SCIM is on and your identity provider hasn’t provisioned them.
- Your identity provider suspended their account over SCIM.
Group mapping
Group mapping puts people in your organization’s groups based on the groups your identity provider sends.
- Groups claim or attribute names the OIDC claim or SAML attribute that lists a person’s groups. The default is
groups. - Each mapping pairs a group name at your identity provider with a group in your organization. Map everyone to a group adds everyone who signs in through the provider to a group.
- On every sign-in, memberships from the mapping are added when the identity provider lists the group, and removed when it no longer does. Memberships added by hand stay.
- Without a mapping, people join with no access until someone adds them to a group or attaches policies to them.
- While SCIM is on, sign-in doesn’t change group memberships. SCIM manages provisioned groups instead.
To change the mapping, open the provider’s Group mapping tab and select Edit mapping. Changes apply from each person’s next sign-in.
Delete an identity provider
Open the provider under IAM > Directory, select Delete, and confirm. People in its domains can no longer sign in with SSO. Their accounts and group memberships stay. Its domains are no longer verified unless another provider lists them, so SCIM stops provisioning people in them.
Limits
| Limit | Value |
|---|---|
| Email domains | One or more per provider, such as example.com. You can’t change a provider’s domains; delete it and add it again. |
| Identity providers added by one user | 10 |
| Identity provider URLs | Public https URLs |
| SAML metadata | 102,400 bytes |
| Group mappings per provider | 100 |
| Group name at your identity provider | 256 characters |
| Groups claim or attribute | 256 characters: letters, digits, _, :, /, . and - |